Trump administration Announces New "Hacking Back" Program

anonymousiam1 pts0 comments

Trump Administration Announces New "Hacking Back" Program

The Volokh Conspiracy

Mostly law professors | Sometimes contrarian | Often libertarian | Always independent

About The Volokh Conspiracy<br>Editorial Independence

Who we are

Books

Volokh Daily Email

Archives

Search

DMCA

- volokh_navigation" data-ga-action="Nav Click - RSS " data-ga-category="Nav Click">RSS

The Trump Administration announced a new program on hacking back last week, allowing United States companies to hack back in some circumstances in cooperation with United States officials.  The program is premised on some interesting theories about the scope of the Computer Fraud and Abuse Act, and I think it raises a lot of complicated issues under that statute.

In this post, I wanted to take a look at some of them.

First, here's the language from the Trump Administration's announcement:

. . . . The National Coordination Center (NCC), established pursuant to section 6(d) of Executive Order 14159 of January 20, 2025 (Protecting the American People Against Invasion), shall create, manage, and maintain a Program to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government.  As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall:

(i)    be overseen by co-Executive Directors, one from the Department of Justice, designated by the Attorney General, and one from the Department of Homeland Security, designated by the Secretary of Homeland Security (Program Executive Directors).  The Program Executive Directors shall be delegated authority to approve, after coordination with each other, cyber operations conducted within the Program by personnel of their respective departments, except that they may not approve operations resulting in Critical Outcomes, as defined in section 4(b) of this memorandum.  Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government's lawful authorities;

(ii)   require Participating Companies to enter into contractual agreements with the Department of Justice or the Department of Homeland Security, which shall ensure that Participating Companies undergo rigorous vetting and that their performance adheres to the strict operational procedures outlined in the implementation guidance directed in section 3 of this memorandum; and

(iii)  permit Participating Companies to enter into commercial agreements with:

(A)  private sector entities, from which the Participating Companies may receive for the purpose of proposing responsive cyber operations to the NCC any threat information collected in the course of those entities' normal business activities; and

(B)  Federal, State, local, tribal, and territorial agencies, which will identify CE-TCO threats to the Participating Companies in a manner that enables them to propose cyber operations to the NCC that address those threats.

(b)  The NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government.

Sec. 3.  Implementing Guidance.  (a)  Within 60 days of the date of this memorandum, the Program Executive Directors shall, in coordination with the Homeland Security Council, establish consensus operating procedures for the Program that ensure the Federal Government's complete oversight and control of Participating Companies' performance.  No operation may be approved unless it complies with these operating procedures.  The procedures shall:

(i)     establish minimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company's ability to perform successfully in the Program;

(ii)    ensure that the Program's eligibility criteria enable participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks;

(iii)   mandate that Participating Companies disclose to the NCC all contractual relationships entered into...

program companies participating operations cyber executive

Related Articles